{"id":"OESA-2026-3852","summary":"flatpak security update","details":"flatpak is a system for building, distributing and running sandboxed desktop applications on Linux. See https://wiki.gnome.org/Projects/SandboxedApps for more information.\r\n\r\nSecurity Fix(es):\n\nA vulnerability, which was classified as very critical, has been found in Flatpak up to 1.10.7/1.12.7/1.14.3/1.15.3.Using CWE to declare the problem leads to CWE-20. The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.Impacted is confidentiality, integrity, and availability.Upgrading to version 1.10.8, 1.12.8, 1.14.4 or 1.15.4 eliminates this vulnerability.(CVE-2023-28100)","modified":"2026-09-13T16:45:49.467461860Z","published":"2026-09-14T16:35:01Z","upstream":["CVE-2023-28100"],"database_specific":{"severity":"Critical"},"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3852"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-28100"}],"affected":[{"package":{"name":"flatpak","ecosystem":"openEuler:20.03-LTS-SP4","purl":"pkg:rpm/openEuler/flatpak&distro=openEuler-20.03-LTS-SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.3-15.oe2003sp4"}]}],"ecosystem_specific":{"x86_64":["flatpak-1.0.3-15.oe2003sp4.x86_64.rpm","flatpak-debuginfo-1.0.3-15.oe2003sp4.x86_64.rpm","flatpak-debugsource-1.0.3-15.oe2003sp4.x86_64.rpm","flatpak-devel-1.0.3-15.oe2003sp4.x86_64.rpm"],"aarch64":["flatpak-1.0.3-15.oe2003sp4.aarch64.rpm","flatpak-debuginfo-1.0.3-15.oe2003sp4.aarch64.rpm","flatpak-debugsource-1.0.3-15.oe2003sp4.aarch64.rpm","flatpak-devel-1.0.3-15.oe2003sp4.aarch64.rpm"],"noarch":["flatpak-help-1.0.3-15.oe2003sp4.noarch.rpm"],"src":["flatpak-1.0.3-15.oe2003sp4.src.rpm"]},"database_specific":{"source":"https://repo.openeuler.org/security/data/osv/OESA-2026-3852.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"}]}